
AMD refused a $10,000 bug bounty to researcher Paul LaRosa after he discovered a critical security flaw in the company's Windows auto-updater. The vulnerability allowed man-in-the-middle attacks via unencrypted HTTP connections. AMD took 124 days to fix the issue but paid nothing, citing policy exclusions.
Tap to vote and see what everyone thinks.
Summary by ByteBrief